Executive brief
A format string vulnerability in multiple Fortinet products allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted packets. The flaw stems from the use of externally-controlled format strings in several versions of FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager.
Affected products
- Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13
- Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14
- Fortinet FortiPAM 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3
- Fortinet FortiSwitchManager 7.2.0 through 7.2.3, 7.0.0 through 7.0.3
Timeline
- 2024-02-15: disclosed: Initial NVD publication date
- 2024-10-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-10-09: advisory: CISA advisory published